Snowpick: Open-source ServiceNow exposure scanner
ResearchServiceNowOur summary
Bishop Fox has developed and released an open-source tool named Snowpick that identifies unauthenticated data exposure in ServiceNow platforms. During authorized penetration tests, the firm scanned 166 ServiceNow instances and found that 31% had exposed data accessible without credentials. These vulnerabilities stemmed from misconfigurations and access control flaws rather than new zero-day exploits. The tool uses public endpoints like Service Portal widgets and the Table REST API to detect leaked information such as ticket attachments, knowledge base entries, and service catalog details. Organizations are advised to audit their configurations using Snowpick to prevent potential incidents.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.